Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 32074 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3735 1 Google 1 Chrome 2025-07-09 N/A 4.3 MEDIUM
Inappropriate implementation in Web API Permission Prompts in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-34872 1 Freedesktop 1 Poppler 2025-07-09 N/A 5.5 MEDIUM
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
CVE-2025-46717 1 Trifectatech 1 Sudo 2025-07-09 N/A 3.3 LOW
sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with no (or very limited) sudo privileges can determine whether files exists in folders that they otherwise cannot access using `sudo --list <pathname>`. Users with local access to a machine can discover the existence/non-existence of certain files, revealing potentially sensitive information in the file names. This information can also be used in conjunction with other attacks. Version 0.2.6 fixes the vulnerability.
CVE-2025-46718 1 Trifectatech 1 Sudo 2025-07-09 N/A 3.3 LOW
sudo-rs is a memory safe implementation of sudo and su written in Rust. Prior to version 0.2.6, users with limited sudo privileges (e.g. execution of a single command) can list sudo privileges of other users using the `-U` flag. This vulnerability allows users with limited sudo privileges to enumerate the sudoers file, revealing sensitive information about other users' permissions. Attackers can collect information that can be used to more targeted attacks. Systems where users either do not have sudo privileges or have the ability to run all commands as root through sudo (the default configuration on most systems) are not affected by this advisory. Version 0.2.6 fixes the vulnerability.
CVE-2025-29448 1 Easyappointments 1 Easy\!appointments 2025-07-09 N/A 7.5 HIGH
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.
CVE-2020-1171 1 Microsoft 1 Python 2025-07-08 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1192.
CVE-2020-1192 1 Microsoft 1 Python 2025-07-08 9.3 HIGH 7.8 HIGH
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings from a notebook file, aka 'Visual Studio Code Python Extension Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1171.
CVE-2023-43037 1 Ibm 1 Maximo Application Suite 2025-07-08 N/A 6.5 MEDIUM
IBM Maximo Application Suite 8.11 and 9.0 could allow an authenticated user to perform unauthorized actions due to improper input validation.
CVE-2021-28967 1 Gimly 1 Matlab 2025-07-08 7.5 HIGH 9.8 CRITICAL
The unofficial MATLAB extension before 2.0.1 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace because of lint configuration settings.
CVE-2025-20202 1 Cisco 1 Ios Xe 2025-07-08 N/A 7.4 HIGH
A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they are processed by the wireless controller. An attacker could exploit this vulnerability by sending a crafted CDP packet to an AP. A successful exploit could allow the attacker to cause an unexpected reload of the wireless controller that is managing the AP, resulting in a DoS condition that affects the wireless network.
CVE-2025-47161 1 Microsoft 1 Defender For Endpoint 2025-07-08 N/A 7.8 HIGH
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2024-43614 1 Microsoft 1 Defender For Endpoint 2025-07-08 N/A 5.5 MEDIUM
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
CVE-2025-21194 1 Microsoft 54 Surface Go 2 1901, Surface Go 2 1901 Firmware, Surface Go 2 1926 and 51 more 2025-07-08 N/A 7.1 HIGH
Microsoft Surface Security Feature Bypass Vulnerability
CVE-2025-20197 1 Cisco 1 Ios Xe 2025-07-08 N/A 6.7 MEDIUM
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
CVE-2025-20199 1 Cisco 1 Ios Xe 2025-07-08 N/A 4.6 MEDIUM
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
CVE-2025-40575 1 Siemens 2 Scalance Lpe9403, Scalance Lpe9403 Firmware 2025-07-08 N/A 4.3 MEDIUM
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices do not properly validate incoming Profinet packets. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted malicious packet, which leads to a crash of the dcpd process.
CVE-2023-29352 1 Microsoft 8 Remote Desktop Client, Windows 10 1809, Windows 10 21h2 and 5 more 2025-07-07 N/A 6.5 MEDIUM
Windows Remote Desktop Security Feature Bypass Vulnerability
CVE-2023-28290 1 Microsoft 1 Remote Desktop App 2025-07-07 N/A 5.3 MEDIUM
Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability
CVE-2022-41121 1 Microsoft 12 Powershell, Remote Desktop Client, Windows 10 and 9 more 2025-07-07 N/A 7.8 HIGH
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2021-34535 1 Microsoft 9 Remote Desktop Client, Windows 10, Windows 7 and 6 more 2025-07-07 6.8 MEDIUM 8.8 HIGH
Remote Desktop Client Remote Code Execution Vulnerability